# IP Intelligence Briefing: 34.79.149.47/32
Classification: Moderate Risk / Cloud Infrastructure IP
Date: 2026-07-29
## Executive Summary
IP address 34.79.149.47 is a Google Cloud Platform (GCP) infrastructure address with a moderate risk score of 40. The IP resolves to Google's user content domain (googleusercontent.com) and is listed on 2 out of 8 DNS blacklists. While the IP shows no active threat indicators or open services, the combination of DNSBL listings and routing anomalies warrants monitoring.
## Technical Profile
Network Classification:
- Provider: Google Cloud Platform (ASN 396982)
- BGP Prefix: 34.79.144.0/20 (origin ASN 396982)
- Route Stability: Stable (0 route changes in past 30 days)
- Geolocation: United States, New York (US-NY)
- Infrastructure Type: Cloud infrastructure with firewalled/no services exposure
DNS Resolution:
- PTR Record: 47.149.79.34.bc.googleusercontent.com
- Forward Resolution: Confirmed to same hostname
- Domain: googleusercontent.com
- DNSSEC: Valid
- CAA Records: Present
Threat Indicators:
- Risk Score: 40 (Moderate)
- Blacklist Count: 2 of 8 DNSBL lists
- Max Severity: High
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Service Exposure:
- Open Ports: None detected
- HTTP/HTTPS: No services exposed
- TLS Certificates: None
## Observation History
Fourteen observations recorded as of 2026-07-29. Recent signals confirm:
- ASN 396982 (Google LLC, US) allocation from ARIN (2018-09-28)
- DNSSEC validation confirmed
- DNS blacklist listings with high severity categories
- Single threat observation count
- No persistent malicious activity detected
## Network Neighborhood Analysis
- Subnet: 34.79.149.0/24
- Neighbor Count: 0
- Abuse Density: 0
- Threat Siblings: 0
The /24 subnet shows no adjacent IPs in the IPDebrief database, indicating isolated cloud infrastructure or limited scanning coverage.
## Relationship Graph
Two DNS associations identified:
- 47.149.79.34.bc.googleusercontent.com (hostname)
No organizational, certificate, or subnet relationships detected beyond DNS resolution.
## Recommended Actions
Immediate Mitigation:
```bash
# iptables
iptables -A INPUT -s 34.79.149.47 -j DROP
# nftables
nft add rule inet filter input ip saddr 34.79.149.47 drop
# nginx
deny 34.79.149.47;
```
Cloud Provider Actions:
- Cloudflare WAF: Block IP with expression `ip.src eq 34.79.149.47`
- AWS WAF: Add IPSet entry for 34.79.149.47/32 with description "IPDebrief risk 40"
## Risk Assessment Narrative
The IP address 34.79.149.47 presents moderate risk primarily due to DNS blacklist listings rather than active exploit activity. The IP resolves to legitimate Google Cloud infrastructure serving user content, which explains the cloud provider classification. However, the presence on multiple DNS blacklists with at least one high-severity listing suggests prior abusive activity from this address or associated IPs.
The firewalled network role with no open services reduces immediate exploit risk, but the blacklist status indicates potential historical compromise or association with malicious infrastructure. SOC teams should monitor for lateral movement patterns from this IP if observed in traffic logs, particularly from internal network segments.
Priority: Medium โ Monitor for traffic patterns, implement blocking rules, and verify if blacklist listings relate to current activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Google LLC |
| ASN | AS396982 |
| Network Name | GOOGL-2 |
| CIDR Block | 34.64.0.0/10 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 47.149.79.34.bc.googleusercontent.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 47.149.79.34.bc.googleusercontent.com |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 56% | 2 | 11 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 30% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 07:49:00 UTC |
| Last Seen | 2026-08-13 06:46:14 UTC |
| Profile Built | 2026-08-13 06:51:13 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 59 |
Full dossier details are available via our API.